Skip to content

Latest commit

 

History

History
28 lines (21 loc) · 1.11 KB

File metadata and controls

28 lines (21 loc) · 1.11 KB

Security Policy

Supported Versions

Only the latest minor release line receives security updates:

Version Supported
1.8.x
< 1.8

Reporting a Vulnerability

Please report security vulnerabilities privately. Do not open a public issue, pull request, or discussion for a vulnerability — that discloses the problem to attackers before a fix is available.

  1. Report privately: Use GitHub's private vulnerability reporting — "Report a vulnerability" under the repository's Security tab. Include a description, the affected version(s), impact, and reproduction steps if possible.
  2. Discussion: We'll work with you on the private advisory to confirm the issue and assess its impact.
  3. Resolution: We'll prepare a fix, release a patched version, and coordinate public disclosure. Reporters are credited unless they ask to remain anonymous.

Your efforts to responsibly disclose your findings are sincerely appreciated.